← All CMRT Flashcard Decks

Privacy & Security Flashcards

7 cards from real CMRT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Privacy & Security flashcards as text
  1. Under HIPAA, which action constitutes a 'minimum necessary' violation?

    Answer: Sharing a patient's entire medical history when only a lab result was requested

    The minimum necessary standard requires limiting PHI disclosures to only what is needed for the intended purpose.

  2. A covered entity's Notice of Privacy Practices (NPP) must be provided to patients:

    Answer: At first service delivery and posted in the facility

    HIPAA requires covered entities to provide the NPP at first contact or service and make it available at their facilities.

  3. Which scenario is an example of an 'incidental disclosure' that is permissible under HIPAA?

    Answer: A patient overhearing their name called in a waiting room

    Incidental disclosures that occur as a byproduct of otherwise permissible communications, like calling a patient's name, are allowed if reasonable safeguards are in place.

  4. What is the purpose of a HIPAA Business Associate Agreement (BAA)?

    Answer: To legally bind vendors who access PHI to comply with HIPAA safeguards

    A BAA is a contract requiring business associates who handle PHI on behalf of a covered entity to follow HIPAA requirements.

  5. Which of the following is NOT one of HIPAA's three categories of safeguards?

    Answer: Financial

    HIPAA's Security Rule specifies administrative, physical, and technical safeguards — financial is not a HIPAA safeguard category.

  6. A patient requests an amendment to their medical record. Under HIPAA, the covered entity may deny the request if:

    Answer: The record was not created by the covered entity

    A covered entity may deny an amendment request if the information was not created by that entity, among other permissible reasons.

  7. Which term describes the process of replacing PHI with a code or pseudonym while retaining a way to re-identify the data?

    Answer: Pseudonymization

    Pseudonymization replaces identifying information with a code, allowing re-identification by the holder of the key, unlike de-identification which removes all identifiers.